惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
Last Week in AI
Last Week in AI
T
Tailwind CSS Blog
WordPress大学
WordPress大学
B
Blog RSS Feed
T
The Blog of Author Tim Ferriss
F
Fortinet All Blogs
aimingoo的专栏
aimingoo的专栏
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
C
Check Point Blog
P
Proofpoint News Feed
H
Help Net Security
月光博客
月光博客
博客园_首页
Stack Overflow Blog
Stack Overflow Blog
博客园 - 三生石上(FineUI控件)
Martin Fowler
Martin Fowler
Recent Announcements
Recent Announcements
人人都是产品经理
人人都是产品经理
U
Unit 42
美团技术团队
I
InfoQ
A
About on SuperTechFans

Help Net Security

Police arrest 10 suspected members of Black Axe cybercrime gang ShinyHunters claims it stole 1.4 million records from Udemy Sevii unveils Cyber Swarm Defense Mode to stop AI-driven attacks at scale Alleged Chinese hacker extradited to US over cyberattacks targeting COVID-19 research Cequence Agent Personas bring granular control and governance to enterprise AI agents NowSecure MARI gives enterprises evidence-based visibility into third-party mobile app risk The metrics killing your SOC, and what to use instead US state privacy fines reached $3.425 billion in 2025 Canada’s first SMS blaster case leads to three arrests Linux storage management tool Stratis 3.9.0 adds online encryption and cache-less pool startup TLS Connect gives SMBs a right-sized automated tool to manage TLS certificates Aptori expands its platform with autonomous offensive testing to reduce security bottlenecks Your IAM was built for humans, AI agents don’t care The AI criminal mastermind is already hiring on gig platforms 25 open-source cybersecurity tools that don’t care about your budget Product showcase: LuLu reveals unauthorized outbound connections from Mac apps Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach Users advised to drop passwords and make room for passkeys - Help Net Security Indirect prompt injection is taking hold in the wild - Help Net Security Compromised everyday devices power Chinese cyber espionage operations - Help Net Security New Cisco firewall malware can only be killed by pulling the plug - Help Net Security Meta is overhauling how you sign in, manage settings, and protect your accounts - Help Net Security Ubuntu 26.04 LTS delivers memory-safe system tools and live patching for Arm servers - Help Net Security OpenAI’s GPT-5.5 is out with expanded cybersecurity safeguards - Help Net Security AI is speeding up nation-state cyber programs - Help Net Security A study of 1,000 Android apps finds a privacy policy logging gap - Help Net Security IT spending to hit $6.31 trillion record, thanks to AI - Help Net Security Where AI in CI/CD is working for engineering teams - Help Net Security With AI's help, North Korean hackers stumbled into a near-undetectable attack - Help Net Security Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security
LastPass customer data exposed through Klue supply chain ...
Sinisa Markovic · 2026-06-24 · via Help Net Security

LastPass disclosed that attackers used OAuth tokens compromised in a supply chain attack on Klue, a market intelligence platform that integrates with CRM and sales tools across organizations, to access customer data stored in its Salesforce environment.

LastPass Klue data breach

“On June 12th LastPass was made aware of an incident that occurred at Klue (klue.com), a third-party market intelligence platform utilized by our go-to-market teams which integrates with our Salesforce and Gong systems,“ LastPass said.

“We immediately launched an investigation and learned that, as part of this incident, an unauthorized actor was able to obtain OAuth tokens Klue held for many of its customers, including LastPass.“

The company said the incident was limited to systems integrated with Klue’s platform and did not affect its products, services, infrastructure, or customer vaults.

According to LastPass, the exposed data included standard business contact information and CRM records, including customer names, phone numbers, email addresses, physical addresses, support case information, and sales-related records.

LastPass warned that the exposed contact details could be used in phishing or social engineering attacks and urged customers to be wary of unsolicited emails, phone calls, or requests for sensitive information, adding that it will never ask users for their master passwords.

After discovering the breach, LastPass revoked employee access to Klue, rotated the exposed API tokens, and launched an investigation with Klue and Salesforce. The company also notified law enforcement and released indicators of compromise, including IP addresses and email sender domains.

LastPass previously suffered a major breach in 2022, when attackers stole customer password vault backups. Three years later, researchers at TRM Labs linked cryptocurrency thefts to credentials recovered from some of the stolen vaults, with on-chain evidence pointing to possible Russian-speaking threat actor involvement.

Klue breach triggers security vendor disclosures

Last week, cybersecurity vendor Huntress acknowledged that it was among multiple companies affected by a breach originating at Klue.

Huntress published a detailed account of the incident on June 18, describing it as a “security domino effect” that began with a compromised integration credential and led to the theft of customer data from several connected platforms, including Salesforce.

Several other security vendors, including Recorded Future, Tanium, and Jamf, have also disclosed their involvement and published statements detailing how they were affected.

An extortion group known as “Icarus,” active since late April 2026, claimed responsibility for the attack on its data leak site.

“Based on our investigation to date, the incident was limited to the affected third-party platforms, and there is no evidence that customer content stored within the Klue platform was impacted,” Klue CEO Jason Smith noted.

“We recognize that customers rely on Klue to securely connect to their systems, and we understand the seriousness of that responsibility.”

“Since identifying the incident, we have been communicating directly with affected customers, sharing investigative findings and supporting their response efforts. Specific remediation guidance has been shared directly with affected customers,” Smith concluded.

According to Klue, the incident was traced to a credential created for a limited pilot project in 2022 that was later used by attackers to access customer data.

“The threat actor will likely continue to post the data of the companies that it compromised from the Klue breach. Icarus will also likely continue to put pressure on impacted organizations to pay a ransom in exchange for not releasing their data,” Huntress stated.

Klue did not say whether it had been in contact with the hackers or planned to negotiate with them.